Skip to content
Snotra Agent ManualThis manual describes Snotra Agent 1.18.2

Why Snotra asks before it acts

Snotra works through tools: it reads files, changes them, runs commands, searches the web. Before any tool call runs, Snotra checks it against fixed rules. The model can ask for anything; whether it happens is decided outside the model, by Snotra itself.

Every tool call belongs to one risk class. The class, together with the mode of the chat, decides whether the call runs, asks you first, or is not offered at all.

Risk classWhat it coversIn Smart, the default mode
ReadReading files and listing folders inside the open folderruns
Read sensitive dataReading a file that may contain credentials, such as .env, a private key or .ssh/asks
ChangeCreating a file or changing one; before a file is replaced as a whole, a copy goes to the trashasks
Overwrite with no way backReplacing a file when no copy can go to the trashasks, every time
ExecuteRunning a shell command or Python codeasks — except a command you told it to always allow
External servicesSearching the web, fetching a page, generating an image, the tools of MCP serversasks, every time

Settings › Tools & security shows these six rows for the open folder, with what applies there and why: See and change what Snotra may do.

Reading inside the folder you opened changes nothing, and you chose that folder yourself. So in Smart Snotra reads without asking — that is what makes it useful.

Sensitive files are different: their content would go to your model provider. The approval card names that provider before you decide. Broad searches and listings leave such files out and only say how many they skipped.

Changes leave traces in your files. You see the new content or the replacement on the card before anything is written.

Commands can do whatever you can do in a terminal. You see the full command on the card before it runs. On macOS and Linux they also run in a sandbox.

External services receive data from your computer: a search query, an address, an image description, the arguments of an MCP tool.

Even in Auto, the mode without questions:

  • No tool reaches outside the open folder unasked. Reading also works in the folders of skills you switched on. Since 1.18 A file tool that wants a file or folder outside asks first on a card, in every mode, Auto included — see Answer an approval request. Your home folder as a whole, the root of a disk and Snotra’s own storage are never offered.
  • Skill folders stay read-only.
  • Snotra’s own settings, keys and permissions are out of reach for every tool.
  • A tool output that contains one of your provider keys is held back.
  • A block you set always wins.

Why loosening goes through a system dialog

Section titled “Why loosening goes through a system dialog”

The chat shows content Snotra did not write: model answers, files, web pages. A text in a file can contain instructions aimed at the model. For the model it is material, not a command, and every tool call that follows goes through the same check again.

That is also why the app window is not trusted to loosen protection on its own. Switching on Auto, allowing something for good, switching the sandbox off or deleting a block is confirmed in a dialog of the operating system, outside the window. Tightening — a block, Always ask — takes effect at once, without a dialog.

Your permissions are stored signed in your profile, not in the project folder. A repository you download cannot switch itself to Auto or turn the sandbox off.